India
14 regulators · 26 instruments · 36 enforcement actions · 9 upcoming deadlines
| Instrument | Type | Year | Regulator | Summary | Source |
|---|---|---|---|---|---|
| RBI Digital Lending Directions, 2025 | Direction | 2025 | RBI | Brings together the RBI guidelines for digital lending (2022) into one Master Direction f… | official |
Brings together the RBI guidelines for digital lending (2022) into one Master Direction for outsourcing to LSPs, first loss default guarantee structure and disclosure requirements. | |||||
| RBI Master Circular — Basel III Capital Regulations (updated annually) | Circular | 2025 | RBI | In order to integrate the current regulatory regime, the Indian banking sector is subject… | official |
In order to integrate the current regulatory regime, the Indian banking sector is subject to a dual track of the Basel III compliance process, whereby banks have to adhere to the existing baseline targets as well as prepare themselves for the upcoming structural reforms. Currently, the existing regulations contained in the April 1, 2025 Master Circular are still valid, in which Scheduled Commercial Banks need to ensure that their Minimum Total Capital amounts to 11.5% of Risk-Weighted Assets, including 9% baseline Capital Adequacy Ratio and 2.5% Capital Conservation Buffer. On the other hand, banks are also in the execution stage of the Capital Charge for Credit Risk – Standardised Approach Directions, 2026. The new rulebook entails the use of very detailed risk weight classification schemes for retail, corporate, and real estate sectors in order for India to become in line with international "Basel III Endgame" standards, all systems being mandatory and effective by April 1, 2027. | |||||
| RBI Master Directions on Fraud Risk Management, 2024 | Direction | 2024 | RBI | The RBI Master Directions on Fraud Risk Management, 2024, which came into effect from Jul… | official |
The RBI Master Directions on Fraud Risk Management, 2024, which came into effect from July 15, 2024, provide a data-driven approach to fast detection and compliance with regard to fraud risk management in banks and other financial institutions. The RBI guidelines require a formal Show Cause Notice to be issued along with a period of 21 days to respond before considering any case as fraud and operational timelines such as 180 days to address flagged accounts. | |||||
| Digital Personal Data Protection Act, 2023 | Act | 2023 | DPBI | The Digital Personal Data Protection Act, 2023, is currently being implemented in phases,… | official |
The Digital Personal Data Protection Act, 2023, is currently being implemented in phases, starting with its gazette notification on 13 November 2025, whereby the Data Protection Board of India (DPBI) was created, and the administrative and penalty jurisdiction of the DPBI came into effect. This is being done through an 18-month phased implementation process, with the next important phase to take place on 13 November 2026, when independent Consent Managers will become functional, culminating in the final deadline of 13 May 2027. After that date, all organizations, whether corporate or governmental, will have to meet various substantive obligations, including data minimization, consent architecture, and 72-hour breach notification. Noncompliance with the requirements of the law after the final date may lead to financial penalties of up to ₹250 crore. | |||||
| RBI Master Direction Information Technology Governance, Risk, Controls and Assurance Practices, 2023 | Direction | 2023 | RBI | RBI’s Master Direction on IT Governance, Risk, Controls and Assurance Practices 2023 that… | official |
RBI’s Master Direction on IT Governance, Risk, Controls and Assurance Practices 2023 that came into full effect from 1 April 2024, lays out a singular regulatory model for cybersecurity and management of IT infrastructure in Indian banks, major NBFCs, and financial institutions. It makes sure that technical responsibility is directly assigned to the Board of Directors through the creation of IT strategy committees, vendor risk controls, and cybersecurity resilience plans. Through this mandate, it overrides previous circulars and legalizes the operational controls by mandating standardized practices like continuous vulnerability assessments, thorough migration data testing, and disaster recovery plans to ensure no operational hitches and safeguard the banking system from technological risks. | |||||
| RBI Master Direction NBFC Scale Based Regulation, 2023 superseded | Direction | 2023 | RBI | The RBI Master Direction on NBFC Scale-Based Regulation, first introduced in 2023 to end … | official |
The RBI Master Direction on NBFC Scale-Based Regulation, first introduced in 2023 to end the now-defunct systemically important assets category system, has officially been superseded by a number of dedicated 2025 Master Directions relating to structure, capital, and registration. Even with the legislative amendment, the fundamental four-level regulatory structure classifying NBFCs based on Base, Middle, Upper, and Top categories as per size and level of systemic risk continues to be in force. The system legally imposes strict bank-style regulation on large financial institutions while also spurring industry-wide transformation in areas such as 90-day NPA classification and higher Net Owned Fund requirement. | |||||
| RBI Master Direction on Outsourcing of Information Technology Services, 2023 | Direction | 2023 | RBI | RBI NBFC (Managing Risks in Outsourcing) Directions, 2025. In spite of this distinction i… | official |
RBI NBFC (Managing Risks in Outsourcing) Directions, 2025. In spite of this distinction in administration, however, the technical requirements in both rule books are the same and enforced after the expiration of the deadline of April 9, 2026, on the old contracts. Under this regulatory framework, there is complete board responsibility for the third-party technological risks. In terms of legislation, financial institutions must be able to have ironclad protections through contract audit rights by the RBI, segregation of cloud data, and a clear multi-vendor exit strategy. | |||||
| CERT-In Directions on Cyber Incident Reporting, April 2022 | Direction | 2022 | CERT-In | The CERT-In Directions on Cyber Incident Reporting, 2022, continue to be valid and consti… | official |
The CERT-In Directions on Cyber Incident Reporting, 2022, continue to be valid and constitute the main statutory requirement for prompt cyber threat mitigation in India. According to the regulation, all individuals or organizations owning or controlling any computer resource must notify specific cyber threats within the very short period of 6 hours from their first identification. As for the reporting period, the regulatory framework mandates several operational requirements that are necessary to prevent any cyber threat – clock synchronization of all systems with NTP and national servers, maintaining system logs for 180 days, and storing all data for 5 years in case of cloud computing and virtual private network service providers. Violation of such directions constitutes a crime under section 70B(7) of the IT Act. | |||||
| Insolvency and Bankruptcy Code, 2016 | Act | 2016 | IBBI | The Insolvency and Bankruptcy Code (IBC), 2016 continues to be a complete and operative l… | official |
The Insolvency and Bankruptcy Code (IBC), 2016 continues to be a complete and operative law in India that serves as the highest and time-bound law that addresses restructurings and liquidations of troubled companies and individuals in the country. Working on the basis of a rigorous ₹1 crore default trigger, this code denies operating authority to the defaulting management and puts the decision in the hands of the independent Insolvency Professional, who in turn works under the guidance of the Committee of Creditors. The whole process of Corporate Insolvency Resolution is limited to a statutory period of 330 days, failing which the company is automatically forced into liquidation. | |||||
| RBI Master Direction Know Your Customer (KYC) Direction, 2016 | Direction | 2016 | RBI | The RBI Master Directions on KYC, 2016 continues to be entirely valid as the final and co… | official |
The RBI Master Directions on KYC, 2016 continues to be entirely valid as the final and constantly up-to-date law in India against money laundering and terrorism financing in the country’s financial industry. The rule is valid for all banks, NBFCs, and payment service providers. It gathers all requirements for customer identification, which includes a thorough categorization of risks and the verification of official documents. With the support of the PMLA, the Master Direction requires constant transaction monitoring, a maximum ownership of 10% in companies, and automatic uploading to the Central KYC Record Registry system. | |||||
| SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015 | Regulation | 2015 | SEBI | The SEBI (LODR) Regulations, 2015, dated 2nd September 2015 and applicable from 1st Decem… | official |
The SEBI (LODR) Regulations, 2015, dated 2nd September 2015 and applicable from 1st December 2015, continue to be in full force and effect as the principal statutory instrument governing listed company disclosures in India. These regulations ensure that public companies are committed to independent board governance, safeguarding of minority shareholders' interests, and establishing compliance committees. With stringent time limits such as Regulation 30, listed companies are required to make timely disclosures of any material event within 24 hours and of the results of board meetings within 30 minutes, along with many other recent innovations such as BRSR Core ESG reporting and rumor checks. | |||||
| SEBI (Prohibition of Insider Trading) Regulations, 2015 | Regulation | 2015 | SEBI | SEBI Regulations on (Prohibition of Insider Trading), 2015, notified on 15 January 2015 a… | official |
SEBI Regulations on (Prohibition of Insider Trading), 2015, notified on 15 January 2015 and operative from 15 May 2015, have been enforced effectively as the main legal framework to stop any undue advantage in the Indian market. The regulation disallows any person who is labeled a connected insider from dealing with listed shares or derivatives when the person is in possession of insider information that is not disclosed to the public. Backed up with strong enforcement measures such as interim freezing of bank accounts and huge impounding orders, the environment requires that all public companies should have an unbreakable Structured Digital Database (SDD). | |||||
| Companies Act, 2013 | Act | 2013 | MCA | The Companies Act, 2013, which was enacted on 29th August, 2013 and subsequently made eff… | official |
The Companies Act, 2013, which was enacted on 29th August, 2013 and subsequently made effective by way of phased implementation is in full operation as the apex legislation that regulates the whole life cycle of companies in India. The Act ensures total financial transparency and provides strong protection to the investors by means of modern mechanisms such as mandatory CSR spend of 2%, strict timelines for auditor rotation, and independent board supervision. The Act is backed by tough enforcement agencies such as SFIO and NCLT and mandates an electronic compliance system including mandatory uneditable audit trail software for book-keeping, 10% or more significant beneficial owner identification, and complete dematerialization of shares of unlisted large companies to stop shell company operations. | |||||
| Foreign Contribution (Regulation) Act, 2010 (FCRA) | Act | 2010 | — | The Foreign Contribution (Regulation) Act, 2010 holds full validity as India’s topmost st… | official |
The Foreign Contribution (Regulation) Act, 2010 holds full validity as India’s topmost statutory instrument dealing with the acceptance and management of foreign contributions in civil society organizations. Despite being highly regulated with inflexible rules like the compulsory route for all international funds through one branch of the SBI at New Delhi, a 20% ceiling on administration costs, and an absolute prohibition on cross-transfers between NGOs, the Act is currently witnessing major structural changes. The revised rules on the Foreign Contribution (Regulation) Act, 2026 have already come into effect and regulate the use of geography-based funding channels and a ₹10 lakh floor requirement for renewal purposes. On the other hand, the comprehensive FCRA Amendment Bill, 2026 is currently pending before the Joint Parliamentary Committee to establish a new Designated Authority for asset management in case of expiry or cessation of the five-year license period. | |||||
| Payment and Settlement Systems Act, 2007 | Act | 2007 | RBI | The Payment and Settlement Systems Act of 2007 is in full operation as India’s primary le… | official |
The Payment and Settlement Systems Act of 2007 is in full operation as India’s primary legislation that ensures security, efficiency, and irrevocability of all electronic fund transfers, card networks, and payment settlement structures. Working under the regulatory control of the Reserve Bank of India and the new Payment Regulatory Board, the Act confers legitimacy to auto-netting procedures and makes errors in auto-debit transactions a criminal offense under Section 25. The structure saw a major revamp after the passing of the Taxation and Other Laws (Amendment) Act in August 2026, which abolished the zero fee requirement for all electronic transactions, creating the framework for charging a nominal Merchant Discount Rate (MDR) above ₹2,000 for large-value corporate and merchant UPI payments, while keeping consumer daily transfers free of cost. | |||||
| Credit Information Companies (Regulation) Act, 2005 | Act | 2005 | RBI | Credit Information Companies (Regulation) Act, 2005 is completely operational as the prim… | official |
Credit Information Companies (Regulation) Act, 2005 is completely operational as the primary legislation of India regarding credit risk information, retail scoring, and bank history pipeline management. By granting powers to the RBI to license and regulate the business, this Act compels all commercial banks, NBFCs and asset reconstruction companies to furnish credit information but keeps the privacy of consumer information intact. There has been a considerable amount of improvement within the regulatory framework through recent changes in its structure, including the requirement of the 1st July 2026 quad-weekly reporting, where lenders have to provide incremental account updates four times a month, a mandatory data rejection cleansing process, and the Internal Ombudsman Scheme of 2026. | |||||
| Competition Act, 2002 | Act | 2003 | CCI | The Competition Act, 2002 enjoys full force and effect as the most superior statutory reg… | official |
The Competition Act, 2002 enjoys full force and effect as the most superior statutory regime in India with regard to the prohibition of market monopolies, cartels, and corporate combinations. Enacted by the executive powers of the Competition Commission of India, the Competition Act, 2002 is a robust instrument used for blocking any agreements that have the ability to cause any appreciable adverse effect on competition and imposing hefty fines on dominant firms that apply their unfair and predatory strategies for excluding rivals. Recently restructured and modernized to an extensive level, the regime has expanded its jurisdiction to digital economy mergers using an Alternate ₹2,000 Crore Deal Value Threshold, fast-tracked settlements and commitments mechanism for businesses, and behavioral sanctions pegged to 10% of global turnover of an enterprise across different products. | |||||
| Prevention of Money Laundering Act, 2002 (PMLA) | Act | 2003 | FIU-IND | The Prevention of Money Laundering Act, 2002 is entirely operational as the major statuto… | official |
The Prevention of Money Laundering Act, 2002 is entirely operational as the major statutory regime of monitoring, impounding, and forfeiture of proceeds of the designated economic offences and institutional corruption in India. Utilizing the cooperative authority of the ED and FIU-IND, the Act shifts the age-old rule of proof of innocence on the accused, where the individual needs to prove the legitimacy of his wealth, along with imposing stringent "twin conditions" for bail. Updated to international FATF guidelines, the regime considers crypto platforms, corporate executives, and trustees in foreign jurisdictions as Reporting Entities mandatorily, which means that the entities need to conduct stringent KYC procedures and report cash transactions within seven days. | |||||
| SEBI (Prohibition of Fraudulent and Unfair Trade Practices) Regulations, 2003 | Regulation | 2003 | SEBI | SEBI (PFUTP) Regulations, 2003 form the most effective piece of legislation in India to c… | official |
SEBI (PFUTP) Regulations, 2003 form the most effective piece of legislation in India to curb capital market malpractices such as market manipulation, manipulation of prices, and collusion of traders in the capital markets. As per the rules under enforcement by SEBI, the market participants are prohibited from creating artificial volumes of trades, indulging in front-running activities, or indulging in deceptive pump-and-dump practices that deceive the investment community. Highly updated in order to deal with modern-age manipulation practices, the PFUTP regulations enable SEBI to monitor colluding mule account operations, break manipulative loop algorithms, and impose disgorgement penalties of crores on the unregistered finfluencers utilizing social media networks. | |||||
| Information Technology Act, 2000 | Act | 2000 | CERT-In | Information Technology Act, 2000 continues to be operative in its totality as the foremos… | official |
Information Technology Act, 2000 continues to be operative in its totality as the foremost legislative instrument for validation of digital contracts, e-governance, and prosecution of cybercrime in India. With its provisions for the creation of equivalence of digital signatures and establishment of the regulatory safe harbor framework for internet intermediaries, the Act is indeed the final legal shield for all internet-based portals, e-commerce ventures, and telecommunication companies. In view of its extensive enforcement powers, including those under Section 69A of blocking orders and mandatory cyber-incident reporting timelines imposed by CERT-In, the framework ensures that the cyber frontiers of India are constantly policed. | |||||
| Foreign Exchange Management Act, 1999 (FEMA) | Act | 1999 | RBI | Foreign Exchange Management Act, 1999 (FEMA) exists as India's primary legal act that gov… | official |
Foreign Exchange Management Act, 1999 (FEMA) exists as India's primary legal act that governs all cross-border financial dealings and foreign investments in the country. As opposed to the FERA times when the regulatory body was backed by criminal sanctions, FEMA acts as a civil regulatory net that divides the flow of funds into the free current account and regulated capital account category in conjunction with the RBI and the Enforcement Directorate (ED). The regulatory structure has been highly reformed by means of introducing various 2026 structural reforms, such as the uniform trade regulations of 2026, revised digital compliance metrics for the Foreign Portfolio Investors (FPIs), and revised compounding Master Directions. | |||||
| SEBI Act, 1992 | Act | 1992 | SEBI | The SEBI Act, 1992, is entirely applicable as the supreme statutory framework for capital… | official |
The SEBI Act, 1992, is entirely applicable as the supreme statutory framework for capital market regulation, investor protection, and mitigating risks in the Indian financial system. Endowed with legislative, investigative, and enforcement powers for regulating the markets, investigating structural problems, and dealing with the non-compliance of corporations, the SEBI Act, 1992, represents the supreme legal boundary of listed securities, derivatives, and intermediary services in the financial markets of India. The Act is underpinned by a judicial process that leads to the Securities Appellate Tribunal (SAT). In this context, the SEBI Act ensures that SEBI can monitor sophisticated threats to the financial market like high-frequency trading irregularities and insider trading schemes worth millions of rupees. | |||||
| Securities Contracts (Regulation) Act, 1956 | Act | 1956 | SEBI | The Securities Contracts (Regulation) Act, 1956 remains fully operative as the fundamenta… | official |
The Securities Contracts (Regulation) Act, 1956 remains fully operative as the fundamental law that stops any form of market manipulation and ensures transparency in the operations of the stock exchanges and clearing agencies in India. The law is responsible for the corporate governance of the exchanges with the help of the mandatory demutualisation laws and confers complete power on SEBI to define financial products and declare off-market deals as invalid. To cater to the huge capital base in modern times, the framework was innovatively revised using the Securities Contracts (Regulation) Amendment Rules, 2026 that substituted the old public float criteria with an intricate six-tier system for IPO allotments. | |||||
| Banking Regulation Act, 1949 | Act | 1949 | RBI | The Banking Regulation Act, 1949, is in full effect as the primary legislative instrument… | official |
The Banking Regulation Act, 1949, is in full effect as the primary legislative instrument for securing the complete solvency, accountability, and stability of the nation’s banking industry. Through empowering the RBI with ultimate interventionist powers to overrule bank management, prevent speculative direct trading, or even revoke commercial bank licences, this Act helps protect depositors' rights by insisting on tough board compositions and liquidity reserves. It has been updated several times by Parliament, with its latest structural amendments in 2025/2026, which have brought great progress in protecting depositors and in corporate governance by allowing a multi-nominee account system and extended terms for cooperative bank management. | |||||
| Insurance Act, 1938 | Act | 1939 | IRDAI | The Insurance Act, 1938, is completely operational and acts as the prime statutory struct… | official |
The Insurance Act, 1938, is completely operational and acts as the prime statutory structure regulating the financial stability, registration, and customer protection structures of the insurance and reinsurance industry. While retaining the base-level customer protections such as the non-repudiation clause that operates for 3 years, the framework saw its biggest change with the Sabka Bima Sabki Raksha Amendment Act, becoming applicable from 5 February 2026. These recent changes brought about the inclusion of revolutionary clauses such as 100% FDI, composite licenses for both life and health insurance, and reduced capitalization restrictions on foreign reinsurers, among others. | |||||
| Reserve Bank of India Act, 1934 | Act | 1934 | RBI | The Reserve Bank of India (RBI) Act, 1934, passed on 6th March 1934 and enforced from 1st… | official |
The Reserve Bank of India (RBI) Act, 1934, passed on 6th March 1934 and enforced from 1st April 1935, is still alive as the top-most legal foundation of central banking, monetary stability, and financial regulation in India. The Act confers upon the RBI the sole legal authority to print currency notes, manages the foreign exchange reserves of India, and uses the Monetary Policy Committee to control inflation through repo rate changes. With the help of enormous powers in Chapters III-B and V, the legal instrument helps the RBI to authorize and regulate commercial banks, impose stringent scale-based risk management for NBFCs, punish non-compliance with regulations, and incorporate the emerging modern finance systems like CBDC (e₹). | |||||
| No instruments match these filters. | |||||